What is Nostr?
rob / Rob
npub1emq…a3jz
2025-01-16 13:19:55

rob on Nostr: PSA: For #plebs playing around building with #nostr You should treat all front end ...

PSA: For #plebs playing around building with #nostr

You should treat all front end code (such as JavaScript) as INSECURE.

It can be manipulated or replaced in browser console by an attacker.

So any data sent to your back end server MUST be sanitized and verified.

Check the schnorr signatures before relying on event data.

That's why Nostr events are SIGNED!
Author Public Key
npub1emq0gngdvntdn4apepxrxr65vln49nytqe0hyr58fg9768z5zmfqcwa3jz